react-native-worklets
The React Native multithreading library
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:eval-usage | AI (semgrep): eval() is the core mechanism of the worklets runtime — it evaluates serialized worklet functions on background threads. This is the intentional, documented design of the library, not a supply-chain risk. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require in validate-react-native-version.js loads a local package.json via __dirname-relative path for version validation. Benign build/validation script pattern. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-classes | AI (phantom-deps): Babel transform plugins are loaded by convention through the Babel plugin system, not via direct imports. Standard pattern for Babel-based tooling. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-unicode-regex | AI (phantom-deps): Babel transform plugins are loaded by convention through the Babel plugin system, not via direct imports. Standard pattern for Babel-based tooling. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-class-properties | AI (phantom-deps): Babel transform plugins are loaded by convention through the Babel plugin system, not via direct imports. Standard pattern for Babel-based tooling. | ai |
Versions (showing 100 of 193)
v0.11.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.9.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.